FortiBranchSASE Ordering Guide

The FortiBranchSASE (FBS) series is purpose-built to provide security and connectivity, intended to be used for small remote sites where local security services are unlikely to be present. In some use cases, customers can streamline deployment by opting to use FBS devices, eliminating the complexity of managing a local security stack at each remote branch.

FBS devices offer fast and versatile connectivity via fiber or copper and establish an IPsec tunnel to the nearest FortiSASE instance for data inspection. FBS devices enable remote management through the FortiSASE portal and deliver security services via SASE cloud or a FortiOS-based solution, such as a remote FortiGate or a cloud-based virtual FortiGate. All traffic generated behind FBS is secured by applying data protection measures at FortiSASE POP or the remote FortiOS instance, ensuring that small remote sites receive robust security and protection. Ordering is simple, select the Hardware FBS device and FortiSASE subscription bundle.

Note: FEX-200F does not have a FortiSASE bundle, please select 595 and 247 which is equivalent to bundle.

ORDER INFORMATION

Hardware Specifications10F-WIFIALL THIN-EDGE MODELS200F
20G20G-WIFI
Dedicated WAN Ports1x 1G RJ45 WAN1x SFP+1G RJ45 (Combo)1x SFP+1G RJ45 (Combo)1x 1G RJ45 WAN
LAN/Switch Ports2x 1G RJ45 WAN/LAN3x 1G LAN, 1x 1G WAN/LAN3x 1G LAN, 1x 1G WAN/LAN3x 1G LAN, 1x 1G WAN/LAN
Power over Ethernet (PoE) PoweredYesNoNoNo
Power RequiredPoE 802.3at (25.5W)12V/2A (24W)12V/2A (24W)12V/2A (24W)
Console Port1x RJ451x RJ451x RJ451x RJ45
USB PortsUSB2.0 - AUSB2.0 - AUSB2.0 - AUSB2.0 - A
BluetoothBLE2.4G BLE2.4G BLEBLE
Connectivity
4G-LTE/5G ModemsNo ModemNo ModemNo ModemNo Modem
Wi-Fi (Built-in AP)NoWiFi6WiFi6No
FortiGate LAN Extension SupportYesYesYesYes
Bandwidth Information
IPsec Throughput890Mbps890Mbps890Mbps900Mbps
Lan-Extension Throughput220Mbps860Mbps900Mbps900Mbps
LAN-WAN, Layer-3 Throughput180MbpsDL/UL: 600Mbps/350MbpsDL/UL: 600Mbps/350Mbps900Mbps
Hardware ModelGlobal (Select the correct region code for Wi-Fi models)
FBS-10F-WiFi-xFBS-20GFBS-20G-WiFi-xFEX-200F
FortiSASE Managed
FortiSASE Subscription BundleFC-10-BS10F-1070-02-DDFC-10-BS20G-1070-02-DDFC-10-BS20W-1070-02-DDN/A
25Mbps Add-on (Account Level) OptionalFC1-10-FSASE-471-01-DDFC1-10-FSASE-471-01-DDFC1-10-FSASE-471-01-DDFC-10-X200F-595-02-DD
FortiSASE Subscription (A-la-carte)FC-10-BS10F-247-02-DDFC-10-BS20G-247-02-DDFC-10-BS20W-247-02-DDFC-10-X200F-247-02-DD
FortiCare Premium Support (A-la-carte)FC-10-BS10F-247-02-DDFC-10-BS20G-247-02-DDFC-10-BS20W-247-02-DDFC-10-X200F-247-02-DD
FortiGate Managed
FortiCare Premium SupportFC-10-BS10F-247-02-DDFC-10-BS20G-247-02-DDFC-10-BS20W-247-02-DDFC-10-X200F-247-02-DD
FortiEdge Cloud Managed
FortiEdge Management + FortiCare PremiumTBDTBDTBDTBD

FREQUENTLY ASKED QUESTIONS

Do FEX-200F and FBS devices provide LTE/5G WAN connectivity?

No. Thin Edge devices are Ethernet-only products in the FortiExtender line, supporting a cost-effective means of rolling out Thin Edge devices via Ethernet, if LTE is not desired and internet connectivity is present at the branch locations for FortiSASE service.

What is the "Thin Edge" concept?

Thin edge refers to a minimalistic approach to deployments where limited on-site equipment is used, focusing on centralized security and control. It's designed for small sites like micro-branches, home offices, and temporary setups that require connectivity with minimal hardware.

What is "LAN-Extension" Technology with FortiGate?

The FortiGate LAN extension allows you to seamlessly connect FortiExtenders and FBS devices into a remote FortiGate at an HQ or centralized location via VXLAN over IPSec. LAN-Extension technology allows FortiGate to extend its local LAN to a remote location using FEX or FBS devices, and hosts connecting behind FBS logically appear as FortiGate's internal LAN and managed from FortiGate. FBS Thin-Edge devices also use LAN-Extension technology to connect to the FortiSASE POP, from where FBS devices are provisioned and managed, thus, connecting hosts behind FBS appliance receive security from FortiSASE cloud.

Does the FBS product line require FortiSASE to operate?

No, while FortiBranchSASE naturally fits with our FortiSASE solution for thin edge deployments, it can also operate with any FortiOS based management solution, such as a remote FortiGate appliance, a FortiGate VM, or FortiGate-as-a-Service.

What licenses do I need to use FortiBranchSASE?

When using FortiBranchSASE units with FortiSASE, a FortiSASE device subscription is required. Select the FortiSASE subscription bundle SKU with appropriate FBS Hardware, apart from 200F which does not have bundle SKU, select a-la-carte SKUs for 200F.

What types of use cases are ideal for FortiBranch SASE?

FBS devices can be used in various use cases and deployment scenarios but three are highlighted below as an example:

How does FortiBranch SASE handles scalability?

Please check current updates for FEX/FBS supported in LAN-Extension mode with FortiGate, it varies between 16 to 1024 devices depending on FortiGate model and FortiGate VM.

Visit www.fortinet.com for more details

© 2024 Fortinet, Inc. All rights reserved. Fortinet, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet's SVP Legal and above, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet's internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.

EBS-OG-R01-20241205

Models: FBS-10F-WiFi-x, FBS-10F-WiFi-x Forti BranchSASE Access Point, Forti BranchSASE Access Point, BranchSASE Access Point, Access Point

File Info : application/pdf, 2 Pages, 468.26KB

PDF preview unavailable. Download the PDF instead.

og-fortibranchsase

References

Adobe PDF Library 17.0

Related Documents

PreviewFortiExtender 211G QuickStart Guide | Fortinet Network Security
Get started with the FortiExtender 211G (FEX-211G) from Fortinet. This quick start guide covers setup, installation, package contents, and regulatory information for securing your network.
PreviewFortiExtender™ Data Sheet: Extend Connectivity and Improve Network Availability
Fortinet's FortiExtender offers scalable, cost-effective, and resilient 5G and LTE solutions, enhancing business continuity and network availability with Security-driven networking. It supports secure connectivity for POS systems, vehicle fleets, and remote operations, integrating seamlessly with the Fortinet Security Fabric.
PreviewSecurity: The Key to a Dependable SD-Branch Solution
Explore how integrating security into SD-Branch solutions is crucial for protecting branch networks from evolving cyber threats, ensuring optimal performance, and managing risks associated with IoT devices and the LAN edge.
PreviewFortiSASE and Zero Trust Ordering Guide
This document provides an ordering guide for Fortinet's FortiSASE solution, detailing remote user subscriptions, branch location connectivity options, account add-ons, training programs, and support services. It explains how FortiSASE extends the corporate perimeter to secure data and enable access to the internet, private applications, and SaaS applications with a Zero Trust framework.
PreviewFortinet Secure SD-WAN Ordering Guide: Models, Bundles, and Specifications
This guide provides comprehensive ordering information for Fortinet's Secure SD-WAN solutions, detailing appliance models, performance specifications, bundle options, cloud integration, and management platforms for enterprise networks.
PreviewFortiSASE 23.4.31 Administration Guide
Comprehensive guide to administering FortiSASE version 23.4.31, covering features like endpoint security, secure web gateway (SWG), network configuration, and analytics.
Preview6 Questions to Ask When Evaluating SD-Branch Solutions | Fortinet
A checklist of six essential questions to help businesses evaluate SD-Branch solutions, focusing on consolidation, performance optimization, intelligent routing, device visibility, traffic inspection, and policy-based controls.
PreviewFortiGate 200F Series: Next Generation Firewall, Secure SD-WAN, Secure Web Gateway Datasheet
Datasheet detailing Fortinet's FortiGate 200F Series, a high-performance network security appliance offering Next Generation Firewall (NGFW), Secure SD-WAN, and Secure Web Gateway capabilities for mid-sized to large enterprises. Features include system-on-a-chip acceleration, advanced threat protection, and simplified management.